Kairos Ransomware Group Strikes Australian Kitchen Design Firm, Steals 540GB of Data
The Kairos ransomware group has claimed another Australian victim, targeting Leisure Coast Kitchens, an NSW-based kitchen design and renovation firm. On 16 September, the hackers posted a leak announcement, alleging they exfiltrated 540GB of sensitive data from the company.
As proof of the breach, Kairos published several files, including:
- Employee driver’s license scans
- A company balance sheet
- Customer correspondence with names and contact details
- A completed tax file number declaration
- An employee’s personal details, including bank account numbers and emergency contacts
Kairos has not disclosed a ransom amount but has threatened to release the full dataset within six days. Leisure Coast Kitchens has not responded to requests for comment.
About Kairos
First detected in November 2024, Kairos has claimed 96 victims to date, though its activity remains relatively low compared to larger ransomware groups. The group typically gives victims seven days to pay, offering a discount for prompt compliance.
This marks Kairos’ second recent attack in the ANZ region, following the July breach of Warwick Fabrics, the New Zealand arm of a global textile supplier. Its most recent Australian victim was LR Reed, a property management firm.
About Leisure Coast Kitchens
Based in Oak Flats, Shellharbour (Illawarra region), the company specializes in kitchen design, construction, and renovations, as well as home offices, outdoor areas, and laundries. It partners with local builders, including Stroud Homes and the Evolution Building Group.
Cederberg Kitchens + Renovations cybersecurity rating report: https://www.rankiteo.com/company/cederberg-kitchens-renovations
"id": "CED1789698286",
"linkid": "cederberg-kitchens-renovations",
"type": "Ransomware",
"date": "9/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': 'Customers with exposed '
'correspondence',
'industry': 'Kitchen Design and Renovation',
'location': 'Oak Flats, Shellharbour, NSW, Australia',
'name': 'Leisure Coast Kitchens',
'type': 'Private Company'}],
'data_breach': {'data_exfiltration': 'Yes (540GB exfiltrated)',
'file_types_exposed': ['Scans', 'Documents', 'Spreadsheets'],
'personally_identifiable_information': 'Yes (names, contact '
'details, bank account '
'numbers, TFN)',
'sensitivity_of_data': 'High (PII, financial, and corporate '
'data)',
'type_of_data_compromised': ['Employee driver’s license scans',
'Company balance sheet',
'Customer correspondence',
'Tax file number declaration',
'Employee personal details (bank '
'account numbers, emergency '
'contacts)']},
'date_detected': '2024-09-16',
'date_publicly_disclosed': '2024-09-16',
'description': 'The Kairos ransomware group targeted Leisure Coast Kitchens, '
'an Australian kitchen design and renovation firm, '
'exfiltrating 540GB of sensitive data. The group published '
'proof of the breach, including employee and customer data, '
'and threatened to release the full dataset within six days.',
'impact': {'brand_reputation_impact': 'Potential reputational damage',
'data_compromised': '540GB of sensitive data',
'identity_theft_risk': 'High (employee and customer PII exposed)',
'legal_liabilities': 'Potential legal liabilities due to data '
'exposure',
'payment_information_risk': 'High (employee bank account numbers '
'exposed)'},
'investigation_status': 'Ongoing',
'motivation': 'Financial gain',
'ransomware': {'data_exfiltration': 'Yes (540GB exfiltrated)',
'ransomware_strain': 'Kairos'},
'references': [{'date_accessed': '2024-09-16',
'source': 'Kairos ransomware group leak announcement'}],
'regulatory_compliance': {'regulations_violated': ['Potential Privacy Act '
'1988 (Australia) '
'violations']},
'threat_actor': 'Kairos ransomware group',
'title': 'Kairos Ransomware Attack on Leisure Coast Kitchens',
'type': 'Ransomware'}